Figure 3: First Embodiment 
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a, A si. a e ■ A = 1 (mod n) 



Generate random 



02 



{r }, i = I,---, k , j = 1,2 , r t j's are small integers 

{e,. | e = (e, (r 12 - r u ) + - + e k {r k2 - r k] ))mod^ , i = l,---,k} 

{e y \e A =(e t + «, ■ r a ) mod $ , e a = -{e, +u t -r l2 ) mod ^ , z" = 1,— >*} 

{<? } is random ordering of {e y } 

M = (aM)modn 



Compute 



Calculate crvoto graph: 






{z v } is reordering of {z v } 






S = M e = ■ fl ( z a z ■ z i2* )) mod » 


«« 





z = Af % mod 



Result 
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Figure 4: Second Embodiment 



Client-side 



Pre-compute: 



01 



a, A s.t. a e ■ A = 1 (mod n) 

g a , b f , B f si. b Sa -B f =1 (mod n) 

g b , b h ,B h s.t. b g »-B h =l(modn) 



Generate random 



02 



e = {f a -g a ) + K={h a + E)-g b + h b = {f a -g a ) + {h a +e)-g b + h c 
ifa. l/ a =(/> a i2-^i)+"- +/^(^-^i))mod^,f = l,---^} 

{K\K =(*«i('«n-^n)+""+*-t('*2-O) n,0d ^' i = 1 »"' 

{^l^=(^i(^-^i)+-" + ^('«-'w)) mDd ^. , ' s=1 »"-'*> 

{^c, I ft c = fad (^12 - tell )+■■■ + K {t<*2 ~ *M )) m0d I* , I' = 1. " ■ . *} 

{/* I Ail = (/<■, + M ; ' ^1 ) m0d </>>fa,2 = (fat + U i -rail) mod ^,1=1, — ,*} 

{*«B I A «1 = + W « ' ) m ° d ^ ' A <" 2 = ^ + Wfll ' ^''^ ^ ' 1 = ! ' " " "'^ 

I = (*« + w h • '«) mod * > Ki = (K + w u ■ ha) mod <f> , i = 1, • • ■ , k) 
{Kj I Kn = (hi + w c, ■ ten ) mod «M«2 = (K, + w c, 'ha) mod *M = 1, — , *} 

} is random ordering of {f aiJ , h m} , h blJ , h clJ } 
M = (a-M)mod« 



Calculate partial cryptographs: 



z ^ - • z fc y - } » reordering of {z i; } 
Sfa = b f ■ [tl( z M ml ■ Z M^ )] ™dn 

Sha = K ■ ( Z hJ"' 2 ■ Z hau" )j m ° d " 

S* = {YI( z m"" 2 • Zkm' 1 )] mod » 

5 fc =^n( z toi' o2 ^te2 ,c ' i )) mod ' 1 

. I £. = fe«l(s«12 - )+ • •■ + gak {Sak2 ~ ^kl))^<f> , * = V" ",*} 



1 st level 



z.. = M % mod « 



{g^ | g afl = (g m + v Bi ■ s ail ) mod <j> , g m2 = (g m + v ai ■ s m2 ) mod <j> , i = 1, - • ■ , k} 
{g bij \g b ix={gu+v bi -s bn )rno&(l>,g bn ={g bi +v br s bl2 )mo&<t>J = \,---,k} 
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Figure 4 Continued 



Calculate cryptographs: 
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52=|5 A -fl(iM i,2 -^2 Si ' , )] m0d ' J 



S 2 =A-S 2 -S hb 
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4, =^ mod « 




S = S, 



negative i 

► Error 



